FeedVulnerabilityHackers exploit info disclosure bug in Gravity SMTP WordPres...
VulnerabilityBleeping Computer
6.0HIGH

Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

📅 19 June 2026 at 20:25 UTC📰 Bleeping ComputerView original source ↗
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin

Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Hackers are exploiting a medium-severity vulnerability in the Gravity SMTP WordPress plugin, allowing them to steal email service credentials and gain detailed information about the site's software stack.

⚙️Technical Details
Affected Systems
Gravity SMTP WordPress plugin
Attack Vectors
/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
💥Impact Assessment
Severity: medium
Who Is at Risk
WordPress site administrators and users with email service credentials exposed through the Gravity SMTP plugin
🛡️Recommended Actions
1Update the Gravity SMTP WordPress plugin to version 2.1.5 or later
2Block requests to '/wp-json/gravitysmtp/v1/tests/mock-data' in web server access logs
3Monitor for suspicious activity and implement additional security measures
📦Affected Products
Gravity SMTP WordPress plugin

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed